haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-129688.8high[patched]

Unauthenticated Stored XSS via Arbitrary SVG Upload

TARGET ECOSYSTEM / VENDORProduct Addons
AFFECTED PRODUCTProduct Addons – WowAddons (< 1.6.15)
CWE CLASSIFICATIONCWE-79: Cross-Site Scripting
PUBLISHED DATE2026-07-01

Summary

Product Addons – WowAddons (< 1.6.15) does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline. This allows an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

Impact

  • Impact: Unauthenticated Stored XSS leading to admin session takeover.
  • Fixed Version: 1.6.15
  • CVSS Score: 8.8 (High)